Metasploit mailing list archives

Re: java_signed_applet questino


From: egypt () metasploit com
Date: Wed, 24 Mar 2010 13:31:11 -0600

You have to set a specific target to be able to use non-generic
payloads.  This is explained in
http://pauldotcom.com/wiki/index.php/Episode185 (linked from the page
you sent).

-egypt

On Wed, Mar 24, 2010 at 1:21 PM, Jeffs <jeffs () speakeasy net> wrote:
thanks Egypt -- I spoke too soon.  I found this demo which explains it all
in detail.

http://www.pauldotcom.com/cgi-bin/mt/mt-search.cgi?IncludeBlogs=1&search=java+applet+

However, I am getting the message exploit failed: No encoders encoded the
buffer successfully

and I presume this is because I did not choose the generic/shell/reverse_tcp
which does encode successfully.  But all demos online show the
meterpreter/reverse_tcp as working.

Any idea on why I cannot get the meterpreter/reverse_tcp to work with this
exploit?


On 3/24/2010 3:04 PM, egypt () metasploit com wrote:

$ gem list
should tell you if rjb is installed.

$ echo $JAVA_HOME
will tell you if the env variable is set.

-egypt


On Wed, Mar 24, 2010 at 1:00 PM, Jeffs<jeffs () speakeasy net>  wrote:


The message in BT4 when running the most recent version of msf3
(3.3.4-dev.8885)  and java_signed_applet of:

"You must install the Java Development Kit, the rjb ruby gem, and set the
$JAVA_HOME variable..."

I know I have the Java Development Kit already installed, and I thought
BT4
has rjb ruby gem installed.

Any help on installing these or verifying if they are installed (other
than
JDK as I know that is installed) for Ubuntu is appreciated.
_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework







_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework


Current thread: